sa-core-2024-001

HIGH CVSS 7.5 drupal
Description

Drupal core REST module allows access bypass under certain configurations.

Timeline
Published
2024-03-20 15:00 UTC
Last Modified
2024-03-25
CVSS Details

CVSS details not available.

Affected Products

No product information available.

CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 7.5 HIGH
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 7.5,
  "datePublished": "2024-03-20T15:00:00Z",
  "dateUpdated": "2024-03-25T18:00:00Z",
  "description": "Drupal core REST module allows access bypass under certain configurations.",
  "id": "SA-CORE-2024-001",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "baseScore": 7.5,
          "baseSeverity": "HIGH",
          "version": "3.1"
        }
      }
    ]
  },
  "severity": "HIGH",
  "source": "drupal",
  "title": "Drupal: Access Bypass in REST Module"
}
View JSON API Download JSON